# Structured logging with Filebeat

**URL:** <https://discuss.elastic.co/t/structured-logging-with-filebeat/269383>\
**Category:** Logs\
**Created:** [April 6, 2021, 9:23pm UTC](https://discuss.elastic.co/t/structured-logging-with-filebeat/269383 "2021-04-06T21:23:40Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![vharabor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vharabor/32/86659_2.png) [@vharabor](https://discuss.elastic.co/u/vharabor)\
**Post date:** [April 7, 2021, 4:33pm UTC](https://discuss.elastic.co/t/structured-logging-with-filebeat/269383/3 "2021-04-07T16:33:41Z")

</div>

We have 5 different docker images doing their own thing.

This post helped me get a little closer but I was hoping to find a more generic solution to parse key value pairs.

> [@Using Grok with KV filter](https://discuss.elastic.co/t/using-grok-with-kv-filter/170136):
>
> Hi, I am pretty new to ELK stack. Currently I am trying to parse my application log using grok pattern. But since my logs are not structured i may have to write too many grok conditions, which will not scale well. Sample log: 2019-02-25 10:22:27,832 LL="INFO" field1="field value" field2="field2val" MTHD="POST" O="ipadd" PAYLOAD="{"errorResponse":{"status":403,"message":"some message.","reason":"some reason"}}" using KV filter I cant parse the above log, as the payload is not parsable using KV…

If we switched to json logging, would that be easier to parse?

---

_[View the full topic](https://discuss.elastic.co/t/structured-logging-with-filebeat/269383)._
